HNHacker News
TopNewBestAskShowJobs

groovecoder

697 karma · joined December 13, 2011

[ my public key: https://keybase.io/groovecoder; my proof: https://keybase.io/groovecoder/sigs/podqLf55xtrfw8jETHPDKY4Px4Ib-tiCmyAKN0bvaCw ]
submissionscomments
groovecoder··on Firefox to Warn When Saved Logins Are Found in Data Breaches
Answered here: https://news.ycombinator.com/item?id=20465981
groovecoder··on Firefox to Warn When Saved Logins Are Found in Data Breaches
Answered here: https://news.ycombinator.com/item?id=20465981
groovecoder··on Firefox to Warn When Saved Logins Are Found in Data Breaches
Disclaimer: Firefox sec eng who works on both this feature and Facebook Container ...

The new 2.x release of Facebook Container allows people to use "Log in with Facebook". To do so, it adds the site into the Facebook Container so sub-resources and 3rd-party cookies are available to the Facebook SDK js.

It warns the user before they enable this on any site.

groovecoder··on Firefox to Warn When Saved Logins Are Found in Data Breaches
Disclaimer: I'm the Firefox sec engineer working on this feature.

Just to clear this up: The code for this is actually way simpler and sends no data to either Mozilla nor HIBP. To prevent Firefox from sending data update pings to HIBP, Firefox Monitor maintains a copy of publicly available HIBP breaches and their metadata [1] in the Firefox "Remote Settings" service. [2]

Using that data, Firefox simply checks for saved logins for breached sites where the saved password is older than the breach. [3]

[1] https://haveibeenpwned.com/api/v2/breaches [2] https://wiki.mozilla.org/Firefox/RemoteSettings [3] https://hg.mozilla.org/mozilla-central/file/6484c07ff8364991...

groovecoder··on Firefox Monitor
Your initial report emails will always go to the affected email addresses.

But future breach alerts will be sent to the Primary address. (If you select that in your preferences.)

groovecoder··on Firefox Monitor
Also, https://www.mozilla.org/en-US/privacy/firefox-monitor/
groovecoder··on Firefox Monitor
https://blog.mozilla.org/security/2018/06/25/scanning-breach...
groovecoder··on Firefox Monitor
By default we don't show:

* Sensitive Breaches * "Retired" Breaches * Spam Lists * Fabricated Breaches * non-Verified Breaches

https://github.com/mozilla/blurts-server/blob/master/hibp.js...

groovecoder··on Firefox Monitor
Good idea. File it here? https://github.com/mozilla/blurts-server/issues
groovecoder··on Firefox Monitor
Disclaimer: Firefox Monitor dev here.

Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.

groovecoder··on Firefox Monitor
https://monitor.firefox.com/security-tips#after-breach
groovecoder··on Firefox Monitor
Disclaimer: Monitor dev here ...

Watch this space: https://github.com/mozilla/blurts-addon/issues/142

;)

groovecoder··on Block Fingerprinting with Firefox
Please note: the fingerprinting protection in this blog post is different from the resistFingerprinting about:config pref which would affect your entropy bits on panopticlick.
groovecoder··on Brave Privacy Browser Is Whitelisting Trackers of Facebook and Twitter
Huh ... I thought that must be a sensationalist headline but sure enough - a fresh download of Brave browser loads facebook.com on pinterest.com.

https://imgur.com/a/M4B9kJ2

groovecoder··on Introducing Firefox Monitor, Helping People Take Control After a Data Breach
We have wrapped the /scan endpoint in rate-limiting to mitigate and alert on abusive scanning. We are fine-tuning the rate limit as we see more real user traffic coming in.
groovecoder··on Introducing Firefox Monitor, Helping People Take Control After a Data Breach
Stay tuned! Localization is our next highest-priority enhancement.
groovecoder··on Introducing Firefox Monitor, Helping People Take Control After a Data Breach
No difference on the site/service side (yet). Stay tuned for more, though! ;)
groovecoder··on Introducing Firefox Monitor, Helping People Take Control After a Data Breach
Thanks for taking the time to provide feedback.

As mentioned in another comment, you can opt-out of the HIBP database here: https://haveibeenpwned.com/OptOut

I also filed https://github.com/mozilla/blurts-server/issues/466 to consider making this visible in the Monitor UI.

groovecoder··on Introducing Firefox Monitor, Helping People Take Control After a Data Breach
Thanks for taking the time to provide feedback.

As mentioned in another comment, you can opt-out of the HIBP database here: https://haveibeenpwned.com/OptOut

I also filed https://github.com/mozilla/blurts-server/issues/466 to consider making this visible in the Monitor UI.

groovecoder··on Why I’m done with Chrome
I'm a Mozillian who worked on MDN for 5 years, and now work on Firefox Privacy & Security. Most relevantly, I wrote the patch that implements strict-origin-when-cross-origin Referrer policy in Private Browsing Mode.

I certainly trust the MDN team to understand how to arrange their content to match their audience.

I also believe web developers should be more informed about the privacy & security issues of their work. The content you tried to add was verbose without any technical detail or links, and the MDN revision history isn't a great space for content discussion.

Have you tried filing a content bug? It's much easier to converse on bugzilla than thru edit battles.

https://bugzilla.mozilla.org/form.doc?bug_file_loc=https%3A/...

groovecoder··on Changing Our Approach to Anti-Tracking
There are known trackers involved with non-consensual crypto-jacking, and fingerprinting. Those domains can be blocked completely.
groovecoder··on Facebook Container for Firefox
We ran a breakage study near the end of last year.

First-Party Isolation (FPI) did have the highest breakage scores: ~18-19% of users reported problems with it, and 9-10% of FPI users disabled the study.

Those are low relative numbers, but at entire-market scale, they are big absolute numbers. :/

https://blog.mozilla.org/data/2018/01/26/improving-privacy-w...

groovecoder··on Facebook Container Extension: Take control of how you’re being tracked
That's an interesting threat model for this particular defense.

Cliqz has done some interesting research in this area of detecting (and stripping) unsafe data elements.

http://josepmpujol.net/public/papers/pujolTrackingTheTracker...

groovecoder··on Facebook Container Extension: Take control of how you’re being tracked
Check out this book:

https://mitpress.mit.edu/books/obfuscation

Full of obfuscation tactics like that.

groovecoder··on Facebook Container Extension: Take control of how you’re being tracked
It still works that way.

We close the previous tab and cancel the webRequest before it's sent to the site so none of the default cookies are sent.

"Converting" a tab from one container to another is actually a bit complicated, and there are open issues for it. :/

groovecoder··on Facebook Container Extension: Take control of how you’re being tracked
Check out https://addons.mozilla.org/firefox/addon/multi-account-conta...
groovecoder··on Facebook Container Extension: Take control of how you’re being tracked
This is essentially a light-weight version of that.
groovecoder··on Facebook Container Extension: Take control of how you’re being tracked
The aim is the same, but ITP only strips cookies after a 24-hour period when you HAVE NOT visited the site.

So ITP does nothing to protect a user who visits facebook.com every day. Which is most of Facebook's user-base.

groovecoder··on Facebook Container Extension: Take control of how you’re being tracked
I really like that perspective! A few more high-profile cases like this and we just might nudge the internet in this direction! :)
groovecoder··on Facebook Container Extension: Take control of how you’re being tracked
My pleasure ... but it's not just my work. Firefox privacy & security and add-ons engineering teams have poured a ton of effort into Firefox Quantum to make features like this possible and easy.
← PreviousPage 2 of 5Next →